A former Capital One employee accessed Capital One 360 customer account information without authorization between January 27, 2017 and April 20, 2017. Exposed data included names, addresses, account numbers, phone numbers, transaction history, dates of birth, and Social Security Numbers. A total of 586 California residents were notified in two waves (July and September 2017). The employee was terminated. Capital One notified the California AG in August 2018.